Re: [Openvpn-users] [Openvpn-devel] OpenVPN and outside clients

2024-01-03 Thread Antonio Quartulli
Sorry, posted to the wrong list. Forwarded to the correct one now. On 03/01/2024 09:41, Antonio Quartulli wrote: Hi, On 03/01/2024 09:14, Peter Davis wrote: Hello, I changed the IP address in the client configuration file, but I can't connect to the server. I got the following error: Wed J

[Openvpn-users] obfs4proxy-openvpn

2024-01-03 Thread Peter Davis via Openvpn-users
Hello, Has anyone used obfs4proxy-openvpn? This project is a bit old and its last update is on Aug 31, 2019. The project URL is https://github.com/HRomie/obfs4proxy-openvpn-linux. Thanks.___ Openvpn-users mailing list Openvpn-users@lists.sourceforge.ne

Re: [Openvpn-users] [Openvpn-devel] OpenVPN and outside clients

2024-01-03 Thread Antonio Quartulli
Resending to the mailing list for completeness (please always keep the mailing list in the CC field) Regards, On 03/01/2024 12:53, Peter Davis wrote: Hello, I changed the IP address in the client configuration file, but I can't connect to the server. I got the following error: Wed Jan 3 10

[Openvpn-users] Transfer from one server to another, compress and digest

2024-01-03 Thread Peter Davis via Openvpn-users
Hello, I have two questions: 1- Is it possible to transfer server and client keys from one server to another or must the keys be generated on each server? 2- I connected to an OpenVPN server with the OpenVPN Connect app on Android, I saw the following two lines in the logs: compress: NONE diges

Re: [Openvpn-users] Transfer from one server to another, compress and digest

2024-01-03 Thread Gert Doering
Hi, On Wed, Jan 03, 2024 at 04:04:02PM +, Peter Davis via Openvpn-users wrote: > I have two questions: > 1- Is it possible to transfer server and client keys from one server to > another or must the keys be generated on each server? Ideally, you wouldn't create the keys "on the server" anywa

Re: [Openvpn-users] Transfer from one server to another, compress and digest

2024-01-03 Thread Joe Patterson
On Wed, Jan 3, 2024 at 11:24 AM Gert Doering wrote: > > Ideally, you wouldn't create the keys "on the server" anyway - in a > secure world, the CA key never leaves a *secure* machine for key generation, > and you'd create server key(s) and client keys on this machine, copying > to the target machi

Re: [Openvpn-users] Transfer from one server to another, compress and digest

2024-01-03 Thread Gert Doering
Hi, On Wed, Jan 03, 2024 at 01:37:54PM -0500, Joe Patterson wrote: > On Wed, Jan 3, 2024 at 11:24???AM Gert Doering wrote: > > Ideally, you wouldn't create the keys "on the server" anyway - in a > > secure world, the CA key never leaves a *secure* machine for key generation, > > and you'd create

Re: [Openvpn-users] Transfer from one server to another, compress and digest

2024-01-03 Thread Antonio Quartulli
Hi, On 03/01/2024 20:03, Gert Doering wrote: Not sure I can come up with a good attack scenario in an OpenVPN PKI scenario where the CA would be stopped from doing something nasty by doing the full .csr dance (because it could still just create arbitrary .key/.crt on its own, thus getting access

Re: [Openvpn-users] Transfer from one server to another, compress and digest

2024-01-03 Thread Gert Doering
Hi, On Wed, Jan 03, 2024 at 10:45:50PM +0100, Antonio Quartulli wrote: > On 03/01/2024 20:03, Gert Doering wrote: > > Not sure I can come up with a good attack scenario > > in an OpenVPN PKI scenario where the CA would be stopped from doing > > something nasty by doing the full .csr dance (because

Re: [Openvpn-users] Transfer from one server to another, compress and digest

2024-01-03 Thread Antonio Quartulli
Hi, On 03/01/2024 23:28, Gert Doering wrote: Hi, On Wed, Jan 03, 2024 at 10:45:50PM +0100, Antonio Quartulli wrote: On 03/01/2024 20:03, Gert Doering wrote: Not sure I can come up with a good attack scenario in an OpenVPN PKI scenario where the CA would be stopped from doing something nasty b